Cipplanner's vulnerability profile centers on its CIPace product, a prominent platform in the industrial control and critical infrastructure planning space. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through authentication and authorization weaknesses such as missing authentication for critical functions, authorization bypass via user-controlled keys, and unrestricted file uploads—flaws that reflect the product's need to balance operational access with security boundaries in safety-critical environments. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cipplanner over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11597CRITICAL An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db | Apr 6, 2020 | 9.8 | 29 | NO | NO |
CVE-2024-50619HIGH Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated u | Feb 11, 2026 | 8.8 | 27 | NO | NO |
CVE-2024-50620HIGH Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user ca | Feb 11, 2026 | 8.8 | 27 | NO | NO |
CVE-2020-11598CRITICAL An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file. | Apr 6, 2020 | 9.8 | 25 | NO | NO |
CVE-2024-50617HIGH Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easi | Feb 11, 2026 | 7.5 | 24 | NO | NO |
CVE-2020-11586CRITICAL An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data. | Apr 6, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-11599HIGH An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user. | Apr 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-11596HIGH A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information | Apr 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-11594HIGH An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file | Apr 6, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-11593HIGH An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send | Apr 6, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cipplanner.
Media articles that mention a CVE ID that affects a product developed by Cipplanner — matched by CVE ID, not by vendor name.